Skip to content
Docs

Reference

Reference for the Emailit SMTP relay, covering host, ports and TLS modes, authentication, From address rules, message size, rate limits and password rotation.

Updated Oct 1, 2026

Use these settings to connect an application, framework or device to the Emailit SMTP relay. Every value here applies to all plans.

Server and credentials

Setting Value
Host smtp.emailit.com
Port 587 (recommended). See Ports and encryption.
Encryption STARTTLS on 587, 2525, 2587 and 25. Implicit TLS on 465.
Authentication AUTH PLAIN or AUTH LOGIN
Username emailit
Password An API key from your workspace, starting with secret_

Each API key’s page in Email APIAPI Keys shows these values on its SMTP Info card.

Ports and encryption

Port Encryption When to use it
587 STARTTLS The default for applications. Use it unless your network blocks it.
465 Implicit TLS When your client only offers “SSL”, or requires TLS from the first byte.
2525 STARTTLS When your host or network blocks 587, which some hosting and cloud providers do.
2587 STARTTLS A second alternative when 587 and 2525 are both blocked.
25 STARTTLS Server-to-server relaying. Many ISPs and cloud providers block outbound port 25, so prefer 587.

STARTTLS ports start in plain text and upgrade to TLS after the STARTTLS command. Port 465 is encrypted from the start. Match the mode to the port: implicit TLS on 587, or STARTTLS on 465, fails during the handshake.

Authentication

  • Methods. AUTH PLAIN and AUTH LOGIN. CRAM-MD5 isn’t supported.
  • Username. Use emailit. Emailit identifies the workspace from the password alone, so the username isn’t checked.
  • Password. A complete API key. Full Access and Sending Only keys both work. A Sending Only key restricted to one domain can only send mail whose From address is on that domain.
  • Without logging in. The relay accepts the connection, but rejects your recipients with 530 Authentication required.

A wrong, deleted or regenerated key returns 535 Authentication failed.

From address rules

Emailit decides which sending domain a message uses from its From header, not from the envelope sender (MAIL FROM).

  • Verified domain. Every address in the From header must be on a verified sending domain of the workspace. Otherwise the message is rejected with 530 From/Sender domain is not verified for this workspace.
  • Exact match. Domains are compared without regard to case, but subdomains are separate domains: to send from alerts@mail.acme.com, verify mail.acme.com.
  • Restricted keys. With a key restricted to one domain, a From address on any other domain is rejected with 530 API key is restricted to sending domain.
  • Paused domains. If sending health paused the domain, messages are rejected with 550 Sending from this domain is paused.
  • Envelope sender. The MAIL FROM address isn’t checked. Emailit replaces it with a bounce address on your domain’s return-path subdomain, so bounces come back to Emailit.

Message size

The maximum message size is 40 MB, measured on the message as transmitted, including encoded attachments. Base64 encoding makes attachments about a third larger. The relay doesn’t announce the limit with the SIZE extension, so a client only finds out after it sends the message: the reply is 552 Message too large (maximum size 40MB).

There’s no fixed limit on the number of recipients per message.

Rate limits

SMTP and the Email API share one set of sending limits per workspace. New workspaces start with 2 messages per second and 5,000 messages per day. The daily count resets at midnight UTC.

Over SMTP, the unit is one transaction: one message, however many recipients it has. Emailit checks the limits when your client sends MAIL FROM, and counts the message toward the daily limit once it’s accepted. When you’re over a limit, the reply is a temporary 452, and most clients retry later:

Text
452 4.4.5 Messages per second limit exceeded (3/2)
452 4.5.3 Daily message limit exceeded (5000/5000)

Pro and Business workspaces get automatic increases based on sending health. Any workspace can ask for more from the Sending Limits card on the dashboard home page. See Limits.

Sandbox mode

Until your workspace has production access, it can only send to the account email addresses of workspace members. Other recipients are rejected when your client sends RCPT TO:

Text
550 Unverified workspaces can only send to workspace members' account emails. Blocked recipient: ada@example.com.

Credits

Each recipient costs 1 credit. Over SMTP, credits are charged when Emailit processes each email, not when the relay accepts the message. If the workspace runs out, the relay still accepts the message, but the emails are held. Top up your credits, then retry the held emails.

Rotate the SMTP password

The SMTP password is an API key, so rotating it means replacing the key. To switch without interrupting mail, create a new key first:

  1. Create a key. In Email APIAPI Keys, select Add API key, give it a name such as SMTP – web app and copy the key. It’s shown only once.

  2. Update your applications. Replace the SMTP password everywhere the old key is used, and restart or redeploy them.

  3. Check the new key. Send a test message, then confirm in Email APILogs that SMTP requests use the new key and the old one has no recent requests.

  4. Delete the old key. Open the old key and select Delete.

If a key has leaked, open it and select Regenerate instead. The old secret stops working immediately, so every application that uses it fails with 535 until you update it. You can also regenerate with Regenerate an API key.

Framework settings

mailer.js
import nodemailer from 'nodemailer';

export const transporter = nodemailer.createTransport({
  host: 'smtp.emailit.com',
  port: 587,
  secure: false,      // STARTTLS; use true only with port 465
  requireTLS: true,   // never send the key unencrypted
  auth: { user: 'emailit', pass: process.env.EMAILIT_API_KEY },
});

For step-by-step setup in specific frameworks and platforms, see Laravel, WordPress, Rails and the other framework guides.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.